Lucene search

K
zdiJuan Vazquez, Rapid7, Inc.ZDI-15-363
HistoryJul 20, 2015 - 12:00 a.m.

(0Day) Hewlett-Packard Client Automation Agent Stack Based Buffer Overflow Remote Code Execution Vulnerability

2015-07-2000:00:00
Juan Vazquez, Rapid7, Inc.
www.zerodayinitiative.com
14

0.735 High

EPSS

Percentile

98.1%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard Client Automation. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Hewlett-Packard Client Automation agent. An attacker can send a large buffer of data to the agent which will cause a stack buffer overflow. An attacker can leverage this vulnerability to execute code under the context of the SYSTEM.

0.735 High

EPSS

Percentile

98.1%

Related for ZDI-15-363